logo
search
Send & Receive Issues

How to Fix External Email Rejection Error 554 5.7.1 Access Denied

Maira MehtabMaira Mehtab Oct 9, 2026 868 views

Question details

External senders are unable to deliver messages to the organization and are receiving a bounce-back message with an access denied error.

Product
Microsoft 365 / Exchange Online
Device & OS
not provided
Scenario
An external user attempts to send an email to a recipient within the organization but the message is blocked by the server.
Observed behavior
The email is rejected, and the sender receives a Non-Delivery Report (NDR) displaying the error code 554 5.7.1 Access Denied.
Before you start

Ensure you have administrative credentials for your Microsoft 365 or Exchange admin center, as resolving this issue requires checking organization-level mail-flow rules and running message traces.

Solution 1Recommended

Run a Message Trace and Update Mail-Flow Policies

Use the Exchange Admin Center to trace the rejected message, identify the blocking restriction, and adjust your organization's mail-flow settings.

Error 554 5.7.1 typically indicates that an organization-level policy—such as a strict mail-flow rule, recipient restriction, or blocked sender list—is preventing the email from being delivered. It is rarely related to mailbox storage limits.

1
Log into Exchange Admin Center

Sign in to the Microsoft 365 admin portal with your administrator credentials and navigate to the Exchange Admin Center.

2
Access Message Trace

In the left-hand navigation menu, go to 'Mail flow' and select 'Message trace'.

3
Run the Trace

Enter the email address of the external sender and the internal recipient. Set the time range to cover when the rejection occurred, then click 'Search'.

4
Analyze the Non-Delivery Report (NDR)

Open the trace details for the failed message. Review the complete NDR to identify exactly which mail-flow rule, connector issue, or recipient restriction triggered the block.

5
Update the Blocking Policy

Based on the trace results, navigate to the relevant settings (such as Mail flow > Rules, or Recipients > Mailboxes > Delivery restrictions) and modify the policy or add the sender to the allow list to permit future emails.

Run a Message Trace and Update Mail-Flow Policies
Administrator Access Required: Standard users cannot perform a message trace or change mail-flow rules. If you are an end-user experiencing this issue, please contact your organization's IT department.
Free Microsoft Office alternative

Upgrade Your Document Productivity with WPS Office

While resolving Microsoft 365 email delivery issues requires admin access, you can independently boost your daily productivity with WPS Office. As a free, lightweight, and powerful alternative to Microsoft Office, it handles all your document, spreadsheet, and presentation needs with perfect compatibility.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install WPS Office: Run the downloaded setup file and follow the simple on-screen instructions to install the suite.
  3. 3. Open Your Documents: Launch WPS Office to instantly view and edit your existing .docx, .xlsx, and .pptx files without formatting issues.
Completely free and lightweight office suiteSeamlessly compatible with Microsoft Word, Excel, and PowerPoint formatsBuilt-in PDF editing, merging, and conversion toolsFamiliar tabbed user interface for quick and easy adoption
microsoft office alternative - wps office

Frequently Asked Questions

What does email error code 554 5.7.1 mean?

This error code indicates that the recipient's email server actively refused to accept the message due to a security policy, mail-flow rule, or strict delivery restriction set by the receiving organization.

Can an individual user fix the 554 5.7.1 Access Denied error?

No. This error is caused by server-side policies and configurations. It requires a Microsoft 365 or Exchange administrator to resolve by adjusting the organization's mail-flow rules or connectors.

Why are only external senders getting this bounce-back message?

This usually happens when the internal recipient's mailbox is configured to 'Require that all senders are authenticated', meaning it will only accept emails from users signed into the same tenant or organization.

How long does it take for mail-flow rule changes to take effect?

Once an administrator updates a mail-flow rule or delivery restriction in Microsoft 365, it typically takes 15 to 30 minutes for the changes to propagate across the Exchange servers.